NIST CSF tables
Summarize
Summarized using AI
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.
Summary of NIST CSF tables
The NIST CSF tables in ServiceNow's GRC application provide a structured framework to manage cybersecurity activities, controls, risks, and related elements aligned with the NIST Cybersecurity Framework (CSF). These tables facilitate tracking, analysis, and reporting of cybersecurity posture, gaps, compliance status, and remediation efforts for various targets, which represent entities under assessment.
Show less
Key Tables and Their Purposes
- Target [sngrctarget]: Represents entities assessed for cybersecurity compliance. It is a shared core table used across GRC applications and content packs to track attributes specific to use cases. Each target uniquely references one entity.
- NIST CSF Activity [snirmnistcsfnistcsfactivity]: Tracks cybersecurity activities associated with targets. Supports gap analysis to identify control gaps, non-compliance, risks, issues, failed indicators, and action plans.
- Gaps [snirmnistcsfm2mpolicystatenistcsfact]: Records control objectives not yet implemented, representing gaps. Useful for detailed reporting and drill-down analysis. It links gaps to targets via a many-to-many relationship.
- Non-compliant Control [snirmnistcsfm2mcxontrolsnistcsfact]: Tracks controls that are implemented but found non-compliant. Supports reporting and drill-down by associating these controls with targets.
- Risk [snirmnistcsfm2mrisksnistcsfactivities]: Captures risks related to implemented cybersecurity controls. Enables comprehensive risk tracking linked to targets for reporting and analysis.
- Issue [snirmnistcsfm2missuesnistcsfact]: Tracks issues associated with controls and risks. Facilitates detailed monitoring and reporting of control-related problems by linking issues to targets.
- Action Plan [snirmnistcsfm2mremediationnistcsfact]: Manages remediation tasks or action plans identified to resolve issues. Supports tracking progress and associating remediation efforts with targets.
- Failed Indicators [snirmnistcsfm2mindicatorsnistcsfact]: Captures failed indicators related to targets, controls, or risks. Useful for monitoring failures and supporting reporting.
- Related Control Objectives [sncompliancem2mpolicystmtpolicystmt]: Manages relationships between control objectives, including parent-child and lateral associations, enhancing the understanding of control dependencies.
Practical Benefits for ServiceNow Customers
- Enables comprehensive tracking and management of cybersecurity activities and compliance status aligned with NIST CSF.
- Facilitates detailed gap analysis and identification of non-compliant controls, risks, and issues.
- Supports effective remediation management through action plans linked to specific issues.
- Enhances reporting capabilities with many-to-many relationships allowing drill-down from targets to related cybersecurity elements.
- Improves control objective management by supporting complex relationships between controls.
A few tables are impacted by the NIST CSF guidance.
| Table | Purpose |
|---|---|
| Target [sn_grc_target] | Target is a core table of design to be shared component among the ServiceNow GRC application and GRC use-case content packs.Target is like entity in its purpose, but is used to track any attributes specific to use-case content packs. No two target records can reference the same entity at any time. |
| NIST CSF Activity [sn_irm_nist_csf_nist_csf_activity] | NIST CSF Activity table is used to track cybersecurity activity relevant for a target. The activity also helps in performing gap analysis that identifies the gaps, non-complaint controls, risks, issues, failed indicators and action plans for a cybersecurity activity. |
| Gaps [sn_irm_nist_csf_m2m_policy_state_nist_csf_act] | Gaps table in NIST CSF is used to track control objectives that aren’t yet implemented as gaps. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Gaps to Targets. |
| Non-compliant Control [sn_irm_nist_csf_m2m_cxontrols_nist_csf_act] | Non-compliant Control table in NIST CSF is used to track controls that are identified as non-compliant. Only cybersecurity control objectives as defined by the framework core which are implemented as controls and non-compliant are tracked. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Non-compliant Controls to Targets. |
| Risk [sn_irm_nist_csf_m2m_risks_nist_csf_activities] | Risk table in NIST CSF is used to track risks that are associated with controls that have been implemented for cybersecurity control objectives as defined by the framework core. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Risks to Targets. |
| Issue [sn_irm_nist_csf_m2m_issues_nist_csf_act] | Issue table in NIST CSF is used to track issues that are associated with controls that have been implemented for cybersecurity control objectives as defined by the framework core. Issues of risks associated with these controls are also included in the metric. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Issues to Targets. |
| Action Plan [sn_irm_nist_csf_m2m_remediation_nist_csf_act] | Action Plan table in NIST CSF is used to track the action plans that are identified for the issues. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Action Plans (remediation tasks) to Targets. |
| Failed Indicators [sn_irm_nist_csf_m2m_indicators_nist_csf_act] | Failed indicators table in NIST CSF is used to track the failed indicators of the target and the control or risk. This table comes handy for reporting and drill down purposes. It's an m2m table that associates Failed Indicators to Targets. |
| Related Control Objectives [sn_compliance_m2m_policy_stmt_policy_stmt] | Related Control Objectives table in NIST CSF is used to track the associations between control objectives. In base implementation, parent and child control objectives are supported, but this table introduces a concept to relate the control objectives at the same level. |